EXECUTIVE SUMMARY
A recent security incident uncovered by the researchers has revealed a concerning new attack vector dubbed "LLMjacking." This sophisticated attack leverages stolen cloud credentials, obtained through a vulnerability in a popular Laravel version (CVE-2021-3129), to target cloud-hosted large language model (LLM) services. Unlike conventional LLM attacks focused on prompt abuse or data manipulation, LLMjacking aims to monetize access to LLM services by selling it to other cybercriminals, leaving the cloud account owner to foot the bill. The attackers meticulously probed the cloud environment, targeting LLM models hosted by various cloud providers, including AWS Bedrock, Azure, and GCP Vertex AI. Through strategic API requests and reverse proxy usage, they cleverly tested the boundaries of their access, aiming to avoid detection while maximizing their exploitation potential.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A recent security incident uncovered by the researchers has revealed a concerning new attack vector dubbed "LLMjacking." This sophisticated attack leverages stolen cloud credentials, obtained through a vulnerability in a popular Laravel version (CVE-2021-3129), to target cloud-hosted large language model (LLM) services. Unlike conventional LLM attacks focused on prompt abuse or data manipulation, LLMjacking aims to monetize access to LLM services by selling it to other cybercriminals, leaving the cloud account owner to foot the bill. The attackers meticulously probed the cloud environment, targeting LLM models hosted by various cloud providers, including AWS Bedrock, Azure, and GCP Vertex AI. Through strategic API requests and reverse proxy usage, they cleverly tested the boundaries of their access, aiming to avoid detection while maximizing their exploitation potential.[emaillocker id="1283"]
In their technical analysis, researchers delve into the intricate methods employed by the attackers to navigate the cloud environment. By issuing seemingly legitimate API requests with intentionally flawed parameters, the attackers probed the availability and activity of LLM services without triggering alarms. For instance, by setting the "max_tokens_to_sample" parameter to an invalid value, they confirmed both access to LLMs and their active status. Moreover, the attackers demonstrated interest in the configuration of the targeted services, indicating a sophisticated understanding of cloud infrastructure.
In conclusion, the LLMjacking attack underscores the evolving landscape of cloud security threats, emphasizing the critical importance of robust defense measures. With cloud credentials becoming a lucrative target for cybercriminals, proactive vulnerability management, secrets management, and comprehensive security posture management (CSPM/CIEM) are imperative. Cloud vendors offer a range of tools and best practices to mitigate such risks, but it ultimately falls upon organizations to implement and maintain a secure cloud environment. By staying vigilant and leveraging industry best practices, businesses can effectively safeguard their data and services against emerging threats like LLMjacking.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Persistence | T1098 | Account Manipulation |
| Defense Evasion | T1564 | Hide Artifacts |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1526 | Cloud Service Discovery |
| Collection | T1530 | Data from Cloud Storage |
| Command and Control | T1090 | Proxy |
| Impact | T1496 | Resource Hijacking |
| T1499 | Endpoint Denial of Service |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/05/researchers-uncover-llmjacking-scheme.html